Item detail
github.com

snyk/agent-scan

RepoRadar surfaced snyk/agent-scan — a developer tool — into the Radar section, where it sits at Gold tier with a 'try now' verdict. Its strongest signal is workflow potential, scored 9.9 out of 10.

Score8.4
Popularity82.0
Riskconditional
TierGold
Score breakdown
Usefulness8.0
Novelty9.0
Momentum8.0
Maturity8.3
Open-source/build8.4
Evidence7.2
Workflow potential9.9
Setup ease8.8

Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.

Why it matters

Useful for security teams that want one CLI to inventory and audit every MCP server, harness, and agent skill installed on a developer machine, and to flag prompt-injection or data-exfiltration patterns before they leak into production. Install via pip, run snyk-agent-scan against a config, and pipe the findings into your existing vulnerability dashboard.

Where this stands now

snyk/agent-scan ranks #266 of 2770 tracked Radar items by composite score (8.4 against a section median of 4.9). The section currently carries 1659 Bronze, 645 Gold, 466 Silver. RepoRadar has retained observations for this record since 2026-06-17 (108 days in the current window). Signal extremes versus the section: momentum at the 83th percentile; novelty at the 93th percentile.

Who should use it

security teams that need one CLI to inventory and audit every MCP server, harness, and skill on a developer machine platform teams building threat-detection pipelines for the agent-skill ecosystem Snyk users who want the same vuln-scanning workflow extended to AI agent components DevSecOps leads who want to detect prompt-injection patterns and data-exfiltration attempts before MCP servers reach production compliance teams building evidence for AI-risk frameworks that require documented adversarial testing

Who should skip it

Pass on snyk/agent-scan if its scope or audience does not match what your team is building right now.

About this signal

snyk/agent-scan is tracked by RepoRadar as a developer tool in the Radar section. First seen 2026-06-17; the source record was last checked on 2026-06-17. The current verdict is 'try now' with a Gold tier and easy setup difficulty. snyk/agent-scan leads on workflow potential (9.9) and novelty (9.0); its lowest signal is evidence quality (7.2), so factor that in before investing setup time. This page summarizes the public evidence on the linked source page and states where additional review is still needed.

How this item is evaluated

The snyk/agent-scan record combines a 8.4/10 composite score with separate popularity (82.0), risk (conditional), and setup (easy) signals. See the scoring methodology for the current weights and evidence definitions.

Questions worth asking before you adopt this

Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.

Risk explanation

scanning MCP configs will execute the commands they declare — run scans inside a sandbox or disposable environment when evaluating third-party configs; experimental CLI output (severity labels, issue codes, response structure) may change between releases — don't bake field names into production dashboards.

Evidence links
Closest alternatives / related signals
agent-security mcp skills prompt-injection vulnerability-scanner inventory snyk python
Verification record

What RepoRadar actually verified

Discovered

Automated discovery and source capture. Last checked 2026-10-03T17:13:14.190776Z.

No editorial or hands-on review is claimed. This record remains at Discovered.

Verification sources

Longitudinal intelligence

How this decision record is moving

Raw history JSON →

87 dated snapshots retained from 2026-06-17 through 2026-10-03; see the snapshot index for explicit coverage gaps. Stars, version, release, pricing, integration, risk, maintenance, verdict, score, and momentum fields remain explicit even when a source has not reported them. Repository momentum is a normalized 0–10 RepoRadar signal; GitHub stars appear only where the popularity monitor retained exact timestamped observations.

RepoRadar score8.4 current · +0.0 net
Repository momentum9.0 current · +1.0 net
GitHub stars (observed)3,110 current · +336 net
GitHub stars3,110 exact observation
Versionv0.6.8
Last release2026-09-29T06:44:00Z
MaintenanceActive
Current riskConditional
Current verdictTry now
Pricing baselineNo structured commercial pricing baseline
Pricing checkedNot applicable or not recorded
Pricing freshnessNo dated commercial pricing review
Integrations baselineModel Context Protocol

Recent dated points

DateScoreMomentumStarsRiskVerdictMaintenance
2026-10-038.49.03,110ConditionalTry nowActive
2026-10-028.49.03,110ConditionalTry nowActive
2026-10-018.49.03,105ConditionalTry nowActive
2026-09-308.49.03,100ConditionalTry nowActive
2026-09-298.49.03,099ConditionalTry nowActive
2026-09-288.49.33,095ConditionalTry nowActive
2026-09-278.49.03,091ConditionalTry nowActive
2026-09-268.49.33,091ConditionalTry nowActive
2026-09-258.49.63,090ConditionalTry nowActive
2026-09-248.49.33,082ConditionalTry nowActive
2026-09-238.49.33,081ConditionalTry nowActive
2026-09-228.49.03,079ConditionalTry nowActive

Why the record changed

Stars change

Stars changed: 3109 → 3110.

Stars change

Stars changed: 3110 → 3109.

Stars change

Stars changed: 3105 → 3110.

Stars change

Stars changed: 3104 → 3105.

Stars change

Stars changed: 3100 → 3104.

Stars change

Stars changed: 3099 → 3100.

Stars change

Stars changed: 3096 → 3099.

Version change

Version changed: v0.6.7 → v0.6.8.

Stars change

Stars changed: 3095 → 3096.

Stars change

Stars changed: 3091 → 3095.

Version change

Version changed: v0.6.7-snapshot-a6af81c-1733 → v0.6.7.

Stars change

Stars changed: 3090 → 3091.